CVE-2017-14995: WSO2 Application Server
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.
Affected products
- WSO2 Application Server: version 5.3.0 only
- WSO2 Business Process Server: version 3.6.0 only
- WSO2 Business Rules Server: version 2.2.0 only
- WSO2 Complex Event Processor: version 4.2.0 only
- WSO2 Dashboard Server: version 2.0.0 only
- WSO2 Data Analytics Server: version 3.1.0 only
- WSO2 Data Services Server: version 3.5.1 only
- WSO2 Machine Learner: version 1.2.0 only
Published 2017-10-04. Last modified 2026-06-17.